|
266311
|
7.5 |
HIGH
Network
|
f5
|
big-ip_application_acceleration_manager big-ip_webaccelerator big-ip_analytics big-ip_domain_name_system big-ip_edge_gateway big-ip_access_policy_manager big-ip_local_traffic_manage…
|
The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1, and 12.…
|
CWE-284
Improper Access Control
|
CVE-2016-5736
|
2024-11-21 11:54 |
2016-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266312
|
7.8 |
HIGH
Local
|
fedoraproject fontconfig_project debian canonical
|
fedora fontconfig debian_linux ubuntu_linux
|
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cach…
|
CWE-415
Double Free
|
CVE-2016-5384
|
2024-11-21 11:54 |
2016-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266313
|
8.1 |
HIGH
Network
|
opensuse haxx canonical debian fedoraproject
|
leap libcurl ubuntu_linux debian_linux fedora opensuse
|
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
|
CWE-416
Use After Free
|
CVE-2016-5421
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266314
|
7.5 |
HIGH
Network
|
debian haxx opensuse
|
debian_linux libcurl leap
|
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leve…
|
CWE-285
Improper Authorization
|
CVE-2016-5420
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266315
|
7.5 |
HIGH
Network
|
haxx debian opensuse
|
libcurl debian_linux leap
|
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
|
CWE-310
Cryptographic Issues
|
CVE-2016-5419
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266316
|
9.8 |
CRITICAL
Network
|
oracle redhat
|
linux enterprise_linux_server enterprise_linux_workstation
|
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5408
|
2024-11-21 11:54 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266317
|
6.1 |
MEDIUM
Network
|
vmware
|
esxi vcenter_server
|
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified v…
|
CWE-93
CRLF Injection
|
CVE-2016-5331
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266318
|
7.8 |
HIGH
Local
|
vmware
|
workstation_player workstation_pro esxi fusion tools
|
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Pla…
|
CWE-426
Untrusted Search Path
|
CVE-2016-5330
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266319
|
7.8 |
HIGH
Local
|
google linux
|
android linux_kernel
|
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Lin…
|
CWE-20
Improper Input Validation
|
CVE-2016-5340
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266320
|
5.9 |
MEDIUM
Network
|
wireshark
|
wireshark
|
epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite …
|
CWE-119 CWE-399
Incorrect Access of Indexable Resource ('Range Error') Resource Management Errors
|
CVE-2016-5359
|
2024-11-21 11:54 |
2016-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|